Monday, February 26, 2024
Broadcom Symantec Messaging Gateway Version Upgrade
The NSFOCUS SAS-H which is hardware end of support and it is not support Edge. You need to use IE mode on Edge to access.
The NSFOCUS SAS-H which is hardware end of support and it is not support Edge. You need to use IE mode on Edge to access.
Using different proxy for individual broswering via broswer shortcut
Using different proxy for individual broswering via broswer shortcut
Sunday, February 25, 2024
Cannot visible the files and folder copy by robocopy (It is visible in old machine)
Cannot visible the files and folder copy by robocopy (It is visible in old machine)
Full data backup from C Drive to external USB driver by using Robocopy
Full data backup from C Drive to external USB driver by using Robocopy
Migrate Broadcom Symantec Messaging Gateway from physical to virtual appliance with different hostname and IP address
Migrate Broadcom Symantec Messaging Gateway from physical to virtual appliance with different hostname and IP address
Saturday, February 24, 2024
Prepare for NTLM disable in your domain environment
Microsoft has made an announcement stating that the NTLM authentication protocol will be disabled in Windows 11. Instead, it will be replaced by Kerberos, which is currently the default authentication protocol in Windows versions above Windows 2000.
https://petri.com/microsoft-disable-ntlm-windows-11/
To prepare for this change is coming, you can enable a GPO to audit what application is using NTLM I n your environment and also what version of NTLM still using?
https://superuser.com/questions/1694421/how-can-i-find-out-what-is-using-ntlm-in-my-environment
https://4sysops.com/archives/auditing-and-restricting-ntlm-authentication-using-group-policy/
Prepare for NTLM disable in your domain environment
Thursday, February 22, 2024
SSL VPN and ZTNA solution requirement on client side control
Solution Requirements |
|
Users experience resemble local office LAN access (F&P) |
Local office LAN is city based |
Connect from Internet or other non-corporate network |
Solution Requirements |
|
ONLY applied on Company owned Laptops with Windows 10 or above, no Apple devices and Android devices |
Always ON (Enforce VPN when network connected) |
MS KB Posture Check and Antivirus Signature Check (Host Scan) |
If the above host scan failed, isolated LAN with limited access will provided instead |
Block any Internet connection when VPN is down |
Supports Captive Portal Authentication (i.e. Hotel Customer Login) |
MFA (Active Directory + Software Token + Cert Auth) |
Detect Antivirus being stop after the VPN connection is established |
SSL VPN and ZTNA solution requirement on client side control
GPO enable Office 365 "click to run" edition to auto update monthly security patches and keep on the target version and channel
GPO enable Office 365 "click to run" edition to auto update monthly security patches and keep on the target version and channel
Failed to login SWIFT RMA port after Edge upgrade
Failed to login SWIFT RMA port after Edge upgrade
Edge Favorites offline migration
Edge Favorites offline migration
Hillstone storeID able to raise support case, download image, access free training, manual and document.
Hillstone storeID able to raise support case, download image, access free training, manual and document.
Tuesday, February 20, 2024
Outlook CVE-2024-21413 aka MonikerLink - Need to patch now
- For .msi install based - you can install standalone security patches to fix this vulnerability
- For O365/M365 user who is using click-to-run edition, assume you are domain joined machine, you need to deploy office GPO to enable auto update and run or deploy the command to run the whole office update. For example:
"C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe" /update user
Outlook CVE-2024-21413 aka MonikerLink - Need to patch now
Migrating a Symantec Messaging Gateway Appliance to the Virtual Edition
Migrating a Symantec Messaging Gateway Appliance to the Virtual Edition
Cisco ASA SSL VPN Vulnerability - CVE-2023-20275
Cisco ASA SSL VPN Vulnerability - CVE-2023-20275
Sunday, February 18, 2024
Hong Kong Monetary Authority (HKMA) - Secure Tertiary Data Backup (STDB)
enhance recovery capabilities from ransomware attacks.
- STDB Governance Model
- Identification of Critical Data
- Data Quality
- Critical Data Lifecycle Management
- Data Extraction and Ingestion
- Secure Repository
- Restoration Planning
- Restoration Validation Process and Drills
- Immutable
- Survivable
- Air-gapped
- Secure
- Controlled
- Verifiable
- Assurance
- Heterogeneous
- High-performance
Hong Kong Monetary Authority (HKMA) - Secure Tertiary Data Backup (STDB)
Tencent Cloud using 3rd parties firewall for Internet edge firewall solution - Fortinet
Tencent Cloud using 3rd parties firewall for Internet edge firewall solution - Fortinet
Tencent Cloud using 3rd parties firewall to between VPC firewall solution - Hillstone
Tencent Cloud using 3rd parties firewall to between VPC firewall solution - Hillstone
Thursday, February 15, 2024
Four MS CVE need to respond and three of them CVE-2024-21412 (CVSS score 8.1) CVE-2024-21351 (CVSS score 7.6) CVE-2024-21410 (CVSS score 9.8) are being ACTIVELY EXPLOITED 0-DAYS vulnerabilities
- CVE-2024-21412 (CVSS score 8.1) and CVE-2024-21351 (CVSS score 7.6) are being ACTIVELY EXPLOITED 0-DAYS vulnerabilities
- CVE-2024-21412 also being exploited by malware.
- Outlook user need to patch the CVE-2024-21413
- Exchange Server CVE-2024-21410 CVE-2024-21410 (CVSS score 9.8)
Bad IP need to block: [IP ADDRESSES] 84[.]32[.]189[.]74 179[.]43[.]172[.]127 179[.]43[.]172[.]191 64[.]31[.]63[.]70 64[.]31[.]63[.]194
Four MS CVE need to respond and three of them CVE-2024-21412 (CVSS score 8.1) CVE-2024-21351 (CVSS score 7.6) CVE-2024-21410 (CVSS score 9.8) are being ACTIVELY EXPLOITED 0-DAYS vulnerabilities
Wednesday, February 14, 2024
End Of General Availability of the Free vSphere Hypervisor (ESXi 7.x and 8.x) (2107518) - Alternative solution
- Smart-X HCI (ELF) https://www.smartx.com/global/community/
End Of General Availability of the Free vSphere Hypervisor (ESXi 7.x and 8.x) (2107518) - Alternative solution
OpenGFW is a flexible, easy-to-use, open source implementation of GFW on Linux - Github
OpenGFW is a flexible, easy-to-use, open source implementation of GFW on Linux - Github
Friday, February 9, 2024
FG-IR-24-029 (Affected version: 7.x) (CVE-2024-23113) - (CVSS 9.8) - Fortinet Fortigate
FG-IR-24-029 (Affected version: 7.x) (CVE-2024-23113) - (CVSS 9.8) - Fortinet Fortigate
FG-IR-24-015 (CVE-2024-21762) (CVSS 9.6) - Fortinet Fortigate firewall
FG-IR-24-015 (CVE-2024-21762) (CVSS 9.6) - Fortinet Fortigate firewall